Understanding the Shift
Insurance industry losses from non-peak perils surpassed $100 billion for the first time in 2025, marking the sixth consecutive year of global insured losses exceeding this threshold. The January 2025 California wildfires alone accounted for $54 billion in economic losses, the highest ever recorded for that peril. Besides wildfires, severe storms, floods, and heat have emerged as significant drivers of claims, impacting infrastructure, supply chains, agriculture, healthcare, and technical installations. Non-peak perils are now economic risks with direct balance sheet impacts.
The Escalating Pattern
The pattern of losses is clear:
- 2020-2025: Six straight years of global insured losses over $100 billion.
- 2025: Non-peak perils alone surpassed $100 billion in industry losses.
- January 2025: California wildfires resulted in $54 billion in economic losses.
- 2017-2025: Reinsurance capital grew at 5.8% annually, reflecting sustained demand for risk transfer capacity.
This trend shows acceleration, not stabilization. Your risk transfer strategy must account for this trajectory.
Identifying Control Gaps
This isn't about traditional control failures. It's about portfolio construction failures. Organizations treating non-peak perils as secondary exposures found themselves underinsured when losses from heat, wildfire, and storms hit multiple regions simultaneously.
Key Gaps:
Inadequate Aggregation Exposure Analysis. Many risk managers focused on peak perils like hurricanes and earthquakes but didn't conduct Aggregation Exposure Analysis for non-peak scenarios. When wildfires struck California and Europe simultaneously, assumed geographic diversification failed.
Heat risk oversight. Heat damage is hard to attribute causally, often falling outside standard property triggers. If your policy doesn't cover heat-related infrastructure failure or supply chain interruption, you're exposed.
Cyber-physical convergence. Munich Re reports that 89% of firms don't feel adequately protected against professional attackers. When heat waves stress power grids and attackers target energy infrastructure, you face compounding losses that traditional cyber and property policies may not cover together.
Static reinsurance structures. Organizations with multi-year reinsurance treaties from before 2023 are finding their programs don't match current loss patterns. Reinsurance structures built for a $50 billion non-peak environment don't perform the same way in a $100 billion one.
Standards and Requirements
No single standard directly addresses non-peak peril portfolio management, but several frameworks highlight requirements that could have identified these gaps:
NIST CSF Core Functions require continuous risk assessment and response planning. The "Identify" function calls for understanding dependencies and critical assets. If you're using NIST CSF for cyber risk but not applying it to physical and climate exposures, you're using the framework selectively.
Insurance Data Security Model Law mandates comprehensive risk management programs, including third-party risk assessment. This means understanding how your reinsurance counterparties model non-peak perils and whether their capacity assumptions align with current trends.
NIS2 (for EU entities) requires risk management measures proportionate to the risks faced, including supply chain security. Heat-related supply chain disruption is explicitly within scope. If you're subject to NIS2 and haven't modeled how extreme heat affects your critical suppliers, you're not meeting the directive's requirements.
Breach Notification Requirements under various data protection regimes require notification within specific timeframes. When heat-related infrastructure failure causes data loss or system unavailability, you must still meet those timelines. Your incident response plan should account for physical events that trigger cyber notification obligations.
Action Items for Your Team
Run a non-peak peril stress test. Model scenarios where severe storms, wildfires, and heat events occur simultaneously across your operations. Don't assume geographic diversification will hold. Calculate the Business Interruption Coverage gap if three non-peak perils hit within the same policy period.
Review your Contingent Business Interruption triggers. Heat damage to supplier facilities may not meet traditional property damage thresholds but can still interrupt your operations. Verify whether your Contingent Business Interruption coverage requires physical damage or extends to operational interruption from infrastructure stress.
Audit your reinsurance counterparties. Ask your broker for the Rate on Line your reinsurers charge for non-peak peril coverage and how that's changed since 2023. If you're self-insured or carry a large retention, understand whether your reinsurance tower is sized for $100 billion+ non-peak years or $50 billion ones.
Map cyber-physical dependencies. Identify where heat-related infrastructure failure could trigger cyber incidents, such as cooling system failure in data centers or power grid instability affecting cloud providers. Confirm your Stand-Alone Cyber Policy and property coverage don't create gaps when both respond to the same root cause.
Pressure-test your Breach Coach engagement model. If a physical event triggers data loss, your breach counsel needs to coordinate with property adjusters and business continuity teams simultaneously. Verify your Insurer Consent Requirement process can move fast enough when multiple coverage lines are implicated.
Update your Underwriting Questionnaire responses. If you're renewing cyber or property coverage and your responses don't reflect how you're managing non-peak perils and heat risk, underwriters will price you as if you haven't adapted. Document your stress testing, supply chain heat risk assessments, and infrastructure resilience investments.
Reinsurance capital grew 5.8% annually over the past eight years. That growth reflects demand, not charity. Reinsurers are pricing for the new loss environment. Your premiums will reflect that reality whether you've prepared for it or not. The question is whether you've done the work to demonstrate you're a better risk than your competitors who haven't.




